Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Praesideo Firmware HIGH 8.8
CVE-2020-6776

A vulnerability in the web-based management interface of Bosch PRAESIDEO until and including version 4.41 and Bosch PRAESENSA until and including ver…

Fix: after 4.41
Fix from $1,950 2021-01-14
Elementor Contact Form Db MEDIUM 6.5
CVE-2021-3133

The Elementor Contact Form DB plugin before 1.6 for WordPress allows CSRF via backend admin pages.

Fix: 1.6+
Fix from $1,600 2021-01-12
Flask Security Too HIGH 7.4
CVE-2021-21241

The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is a independently maintained versio…

Fix: 3.4.5+
Fix from $1,950 2021-01-11
Wdja Cms MEDIUM 6.1
CVE-2020-23631

Cross-site request forgery (CSRF) in admin/global/manage.php in WDJA CMS 1.5 allows remote attackers to conduct cross-site scripting (XSS) attacks vi…

No fix yet
Fix from $1,600 2021-01-11
Fork Cms HIGH 8.8
CVE-2020-23960

Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Fork before 5.8.3 allows remote attackers to perform unauthorized …

Fix: 5.8.3+
Fix from $1,950 2021-01-11
Policy Authority For Unified Communications MEDIUM 6.5
CVE-2020-35722

CSRF in Web Compliance Manager in Quest Policy Authority 8.1.2.200 allows remote attackers to force user modification/creation via a specially crafte…

No fix yet
Fix from $1,600 2021-01-11
Ninja Forms MEDIUM 6.5
CVE-2020-36174

The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.

Fix: 3.4.27.1+
Fix from $1,600 2021-01-06
Network Security Management MEDIUM 6.5
CVE-2020-7336

Cross Site Request Forgery vulnerability in McAfee Network Security Management (NSM) prior to 10.1.7.35 and NSM 9.x prior to 9.2.9.55 may allow an at…

Fix: 9.2.9.55 / 10.1.7.35+
Fix from $1,600 2021-01-05
Curam Social Program Management HIGH 8.8
CVE-2020-4942

IBM Curam Social Program Management 7.0.9 and 7.0.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious a…

Mitigation only
Fix from $1,950 2021-01-04
Cloud Pak System HIGH 8.8
CVE-2020-4917

IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tran…

Fix: 2.3.3.3+
Fix from $1,950 2021-01-04
Mk Auth HIGH 8.8
CVE-2021-21495

MK-AUTH through 19.01 K4.9 allows CSRF for password changes via the central/executar_central.php?acao=altsenha_princ URI.

Fix: after 19.01
Fix from $1,950 2021-01-04
Pagelayer HIGH 8.8
CVE-2020-35944

An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF, which can lea…

Fix: 1.1.2+
Fix from $1,950 2021-01-01
Xcloner HIGH 8.8
CVE-2020-35950

An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almost any endpoint).

Fix: 4.2.153+
Fix from $1,950 2021-01-01
Openemr HIGH 8.8
CVE-2018-16795

OpenEMR 5.0.1.3 allows Cross-Site Request Forgery (CSRF) via library/ajax and interface/super, as demonstrated by use of interface/super/manage_site_…

No fix yet
Fix from $1,950 2020-12-31
Gs716t Firmware HIGH 8.8
CVE-2020-35778

Certain NETGEAR devices are affected by CSRF. This affects GS716Tv3 before 6.3.1.36 and GS724Tv4 before 6.3.1.36.

Fix: 6.3.1.36+
Fix from $1,950 2020-12-30
Site Offline HIGH 8.8
CVE-2020-35773

The site-offline plugin before 1.4.4 for WordPress lacks certain wp_create_nonce and wp_verify_nonce calls, aka CSRF.

Fix: 1.4.4+
Fix from $1,950 2020-12-29
Joomla\! MEDIUM 6.3
CVE-2020-35615

An issue was discovered in Joomla! 2.5.0 through 3.9.22. A missing token check in the emailexport feature of com_privacy causes a CSRF vulnerability.

Fix: after 3.9.22
Fix from $1,600 2020-12-28
Zammad MEDIUM 5.4
CVE-2020-26033

An issue was discovered in Zammad before 3.4.1. The Tag and Link REST API endpoints (for add and delete) lack a CSRF token check.

Fix: 3.4.1+
Fix from $1,600 2020-12-28
Cxuucms MEDIUM 6.5
CVE-2020-35347

CXUUCMS V3 3.1 has a CSRF vulnerability that can add an administrator account via admin.php?c=adminuser&a=add.

No fix yet
Fix from $1,600 2020-12-26
User Registration \& Login And User Management System With Admin Panel HIGH 8.8
CVE-2020-26766

A Cross Site Request Forgery (CSRF) vulnerability exists in the loginsystem page in PHPGurukul User Registration & Login and User Management System W…

No fix yet
Fix from $1,950 2020-12-26
Nagios Core HIGH 8.8
CVE-2020-35269

Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, like adding – deleting for host…

Mitigation only
Fix from $1,950 2020-12-23
Mediawiki HIGH 8.8
CVE-2020-35626

An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an anti-CSRF token and therefor…

Fix: after 1.35.1
Fix from $1,950 2020-12-21
User Registration \& Login System With Admin Panel HIGH 8.0
CVE-2020-35273

EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in t…

Mitigation only
Fix from $1,950 2020-12-21
Storeever Msl2024 Firmware HIGH 8.8
CVE-2020-7201

A potential security vulnerability has been identified in the HPE StoreEver MSL2024 Tape Library and HPE StoreEver 1/8 G2 Tape Autoloaders. The vulne…

Fix: 5.40 / 7.30+
Fix from $1,950 2020-12-18
Planning Analytics MEDIUM 6.5
CVE-2020-4764

IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tr…

Patch available
Fix from $1,600 2020-12-18
Interscan Web Security Virtual Appliance CRITICAL 9.8
CVE-2020-8465

A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate system updates using a combinat…

No fix yet
Fix from $2,300 2020-12-17
Interscan Web Security Virtual Appliance HIGH 8.8
CVE-2020-8461

A CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to get a victim's brow…

No fix yet
Fix from $1,950 2020-12-17
Platform Manager HIGH 8.8
CVE-2020-25095

LogRhythm Platform Manager (PM) 7.4.9 allows CSRF. The Web interface is vulnerable to Cross-site WebSocket Hijacking (CSWH). If a logged-in PM user v…

Mitigation only
Fix from $1,950 2020-12-17
Eps Tse Server 8 Firmware HIGH 8.8
CVE-2020-28931

Lack of an anti-CSRF token in the entire administrative interface in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to force an …

No fix yet
Fix from $1,950 2020-12-16
Financial Transaction Manager For Multiplatform MEDIUM 6.5
CVE-2020-4904

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 is vulnerable to cross-site request forgery which could allow an attack…

Patch available
Fix from $1,600 2020-12-16